message_journal_max_size = 5gb
My query is regarding the journal disk size. The default configuration is 5GB. I am planning to have 100GB of file system on each graylog nodes and planning to assign at least 50GB to message_journal_max_size. Is this a recommended setting? What are the recommended settings or optimal values?
The reason why I am asking this because let’s assume that the journal reaches 40GB if the downstream elastic search was down. When the downstream (elastic search) is back up during dequeuing of messages from the journal will there be any performance impact on the graylog or on the elastic search? Has anybody tested this or has any comments.